Live data from Hacker News

I'm giving up on PGP

blog.filippo.io

131–140 of 350 posts

Re: I'm giving up on PGP

#131

Earlier quoted context omitted.

A functional WoT should be no more difficult to use than managing your Facebook friends or contacts on your phone. Neither of those are difficult tasks, and are achieved by normal users every day.

Yeah I'm sure it's ridiculously simple and all the experts here saying it looks like the idea itself is fundamentally flawed are wrong.

I never said it was simple, and nobody is. It's clearly not a simple problem, or we'd have a better solution by now!

Re: I'm giving up on PGP

#132
post #64
post #32

Earlier quoted context omitted.

> I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here. I don't think the "WoT" is conceptually flawed, and frankly, the argument that "people of average intelligence" can't grasp the concept comes from a very high horse and is also untrue. It's simply that any and all software for PGP utterly fails in the UX and functionality department when it comes to key management. Web of Tr…

The standard for adoptability isn't the average person at their peak hours of attention and focus. It's the drunk teenager at 2 in the morning fumbling around in the dark.

You might want to reconsider your analogy. When I was a drunk teenager at 2 in the morning fumbling around in the dark, my attention and focus was at 110%!

Re: I'm giving up on PGP

#133
post #10

gpg is promoted as a kind of swiss army knife of privacy, but its interface always puts email first. If you use it for something else, you must paranoidly guard every command so that it doesn't by mistake publish information about your privately used keys, for example.

Very true. A high-quality library (that was actually built as a library) for OpenPGP would be a very valuable thing to have.

Re: I'm giving up on PGP

#134

9/10 end users just don't understand that security and convenience are inversely related.

Systems like Signal and WhatsApp show that that's not necessarily true to the degree of previous solutions.

I think that the analysis is a little more involved than that. Roughly, I'd say that at any given point you can make "trivial" tradeoffs between security and convenience. However there can be some groundbreaking advances in one that don't cost you on the other. And then that point you may be able to do a "trivial" rebalance if you'd like.

Re: I'm giving up on PGP

#135
post #25

Earlier quoted context omitted.

From my experience - the only PGP users I've spoken to were all on Keybase or interested in a Keybase invite. It was about 6 people for the entirety of last year - and 3 people this year...it certainly has a problem of "almost nobody uses it" but Keybase seems to have eased things slightly - or at least made it easier to discover people who also use PGP. I see the two problems being "People don't bother with the clun…

I have a keybase account and don't really use it. I like the idea, but part of the issue for me is attaching my "real name" to various online identities. I've used different types of pseudonyms over the years and do to poor opsec, some of them could be linked to me using the pseudonyms I use now. It's nothing illegal, but also nothing I'd like others to know about. So to attach my real name to keybase, I'd have to re…

I believe one of the creators had said it is okay to have multiple accounts to keep identities separate or even to have an account for each identity. It does make it far less user friendly to need multiple accounts and multiple keys though and introduces a larger chance of making mistakes. Especially if it isn't that important to you (and it doesn't need to be!)

I use KB as an easy way for people to verify my signed messages - not necessarily for sending encrypted messages to other users. Mostly just a "This is me, you can verify it is me at Keybase easily - as long as you trust Keybase."

Doing that means users don't need to install PGP and know how to use it to verify that I am me. It isn't important now - or hopefully ever. By making a practice of it, my users expect it. if I am ever compromised, the malicious actor won't succeed in fooling my users as I expect at least a few will try and verify the message and will see it doesn't verify.

For myself, it's about being a solution for a "what if?" scenario than anything practical or even privacy-related. It's just the best psuedonymous way of proving identity within some level of reasonable doubt that I know of.

Re: I'm giving up on PGP

#136

People who use PGP keys, can you give examples of your use? I'm genuinely curious. Who are you contacting, or who is contacting you? The author says he only receives 2 encrypted emails a year. Not only do I not have a PGP key, I don't think I've ever found myself in a situation where it was even an option to use one.

I've only ever used my PGP key for two purposes:

- to sign tags in Git for open source projects that I maintain

- to sign custom packages I build (and host) for Arch Linux

Re: I'm giving up on PGP

#137

The conclusions here (avoiding long-lived per-identity keys and having the option to easily rotate and re-validate per-device keys) are very much what we've aimed for in the end-to-end crypto for Matrix.org ( https://matrix.org/blog/2016/11/21/matrixs-olm-end-to-end-en... ). Rather than using a silo like Signal or WhatsApp, it is possible to get the flexibility of an open federated network built on an open standard,…

When I mention Matrix, a lot of people seem to pigeonhole it as a chat system alone because Riot is such a dominating part of the application ecosystem.

It would be really great to have more code and demonstrations available; adding Matrix was suggested for Mastodon[0] to potentially gain chat and private messaging features that aren't part of GNUSocial, but as of right now it's considered out of scope.

[0] https://github.com/Gargron/mastodon/

Re: I'm giving up on PGP

#138
post #5

After all that, he was only getting two encrypted emails a year! Damn. That's crazy.

The deepest I ever got into active PGP/GPG was in college (where it is certainly easiest to have WoT key signing parties) and so far as I recall none of us ever really bothered encrypting anything to each other, we just signed a most of our emails as something of a prideful badge that didn't really mean much all things told. (To the point where at least one friend made a joke fake PGP signature that wouldn't verify t…

I did exactly the same, signature as a badge of being one of "those guys". In the days of 56 bit "international edition" Netscape (or slightly thereafter, but still heavily influenced by that early wave of NSA-awareness), it felt like being way ahead of the curve. Kudos to the guy with the fake signature, in hindsight I must say that he truly nailed it.

One day however, my bank started offering transaction notifications by email, with optional PGP encryption. Suddenly there was real utility, and without any trace of WoT issues (key exchange over the same web frontend already trusted for actually transferring money, and the key in question is only for read-only messages). Other than that, the only encrypted messages I receive are the ones I send to myself as a convenient (because everything is already set up) form of secure cloud storage.

Re: I'm giving up on PGP

#139
post #113

> Yeah, about that. I never ever ever successfully used the WoT to validate a public key. If you ever installed a Debian package then you did. A long-term identity as "Bob Jones" might not be terribly useful - but that's not the kind of long-term identity we care about a lot in real life either. A long-term identity as "Debian release manager" or "Signatory on bank account xyz" or even "Wikileaks committee member" is…

> If you're using iOS you've already given up against state-level attackers. Wasn't the recent apple vs FBI debacle evidence to the contrary?

It ended because FBI just cracked the device anyway. How is it contrary?

Re: I'm giving up on PGP

#140
post #13

I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification. It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "…

"I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here." I think it's the key model that's fundamentally flawed rather than pgp itself, which I believe the author of the article is also asserting. In cryptography, it is often explained that despite the fact a one-time pad is guaranteed-secure (given various conditions I'm eliding), it is not practical in the vast majority of cases…

> How do you distribute the one time pad in the first place?

Something I've wanted to make for a while now, that should be possible to make with almost any cheap embedded microcontroller, is a hardware dongle that stores OTP pads. This would be a generic character device that could be integrated into existing chat programs.

* Each device has a hardware RNG, e.g. [1] or similar

* A port that allows two devices to connect. When connected, they each start generating random numbers, sending a copy to the other device. They both store the XOR of each device's random number as the pad.

* A USB interface accepts plaintext, the device generates the cyphertext, while enforcing deletion of the used portion of the pad. Decryption is handled with a similar interface, so the pads never leave the device.

* The device would provide to the host how much pad is remaining, to be used in the UI. Warnings should be provided when the pad is running low, etc.

The goal is to utilize existing knowledge and experience. Schneier (and others) recommend[2] that passwords be written down because people's understanding of physical security is better than their chances of memorizing enough entropy to actually make a usable password.

This isn't trying to solve the general WoT problem. Instead, it tries to solve a piece of it in a way that most people can understand. Connect devices when you meet in person, and you gain a certain amount of secure chat. Refill by meeting in person again.

It would be easy to extend this idea to provide other features (e.g. generating pubkeys), but since the goal is a simple device that is easy to understand, avoiding feature creep is important, at least initially. Features like WoT will be easier to implement if there is existing infrastructure that can be exploited.

[1] http://holdenc.altervista.org/avalanche/

[2] https://www.schneier.com/blog/archives/2005/06/write_down_yo...

Post reply on HN